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1 • We have informally reviewed subject IG report with 
? , n J p J ctor General and generally concur with its findings, 
firm b ^ lieve that recommendation 4c requires further clarifica- 
tion Recommendation 4c. states: -'The Office of Security should 
4 g , VC !? P rime responsibi 1 ity over enforcement of security 
couT^H s .P^ escr ibed for CIA contractors." This recommendation 
e S,K in terpreted in several ways. One, a responsibility to 
a ^Olo securit y poixcy, procedures and standards to include 
all°of ^h. e ^ Ure ^ a 1 1 " UCh standards are being met; and two, 
inHnct • f above P lus the day-to-day implementation dealing witJi 
Drommmat • COI } tractors on the multitude of decisions which affect 

tiSn cou?H WCl1 35 securit y- This second interpreta- 

wriI]1 j , Id result m fragmentation of contract management and 

revi^ e jft COnC f r ? t0 DD/S6T - 0ur rationale, together with a 
revised statement for recommendation 4c is discussed below. 

n rnfiv ^’ DD/S 4 T usestbe Management Team concept to support the 
T Manager m directing a contract program. The Management 

l'-pai °hnrlopr / ? ■ specialists to provide the technical, contractual/ 
^ > budget/finance, logistics, audit, communications, and 

arp U fl q^ii fooct ions . The Security Officers for a Management Team 
2^*® d t0 bD/S. f T by the DDA Office of Security. The 

Contract Officer Budget and Finance Officer, Auditor, and 
Communications Officer are also assigned to the DD/S5T by the 
appropriate offices of the DDA. Thus, the Program Manager with 
1 fo i a particular technical nr op ram 

ttt tbeaccc J 5ar y expertise to properly and efficiently manage 
the contractor's activities. The contractor has one focal point 
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to deal with* and receives coherent direction and support, 
furthermore, the Program Manager is responsible for the single 
legal enforcement tool available -- the contract which contains 
performance . incentives and penalty clauses. (Note: future 
contracts will require new language to provide the leverage 
needed to strengthen the Government's ability to enforce proper 
security). Contract management is a continuing set of tradeoffs 
over the life of a contract. Such tradeoffs include technical 
solutions, schedules, and costs. Many tradeoffs also have 
security implications which must be factored into the decisions, 
for example, tradeoff judgments may have to be made involving 
the technical requirements of a specific test program, the 
security restrictions that must be applied, and the costs of 
those activities. "Security by the Book" without specific 
tailoring to the test program could make it impossible to con- 
uct the testing. On the other hand, waiving some aspect of 
security in order to conduct the tests could result in blowing 
a sensitive development. Thus, there needs to be a day-to-day 
interaction between the Security Officer and the other elements 
of the Management Team to ensure program progress while main- 
taining proper security. 
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3- For the above reasons , DD/SfT strongly believes that 
the Agency responsibility for implementing industrial security 
policy and procedures should remain a line function from the 
Program Manager to the contractor. To remove from the Program 
Manager the responsibility for implementing industrial security 
(or one of the other essential elements of program management) 
would be detrimental to effective contract management and could 
result m several sources of directions to the contractor. 


4 - DD/SST agrees that the Office of Security should have 
ull responsibility for establishing Agency security policy, 
procedures, and standards. This 0/S function should be 
strengthened as necessary to improve and clarify existing 
octrine and regulations. The 0/S also has the responsibility 
lor industrial personnel security investigations and establish- 
!n j :md maintaining clearances for i n . i i: : , : r : 1 personnel. That 
responsibility should continue and be strengthened by incorpora- 
tion of polygraph procedures as recommended' by the I.G. DD/S^T 
elieves that the responsibility for implementation of 
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SUBJECT: 


IG Report on CIA Security Performance Rela ted to 
Problems - 


industrial security policy and procedures should remain a 
Jr r nHt reS ?! nSlb r\ lty of the Program Manager supported by the 

h 7 ? fflcer C s ) on hl $ Management Team. Stricter attention 
rnntrart g i veri to this responsibility by the Program Manager and 
rn»l ? documentation must be strengthened to enhance security 
sernv?i ° f con J ract °P' To ensure proper implementation of 
rm/sr? L? r0Cedl ? re !, by f ro £ ram Manager and by the contractors 
. ' ^ recommends that 0/S be given a security audit responsibil- 

tn rn a s a Pa r < a t< e se cu r i t y audit team should be established in 0/S 
T>*° ndU Z t P eriodlc announced and unannounced inspections of 
f p°? ram Management and the contractors. Thus, 0/S could ensure 
that. proper security standards are being maintained or could 
require corrective action through the Program Manager. This 

thr !uf ent check on the implementation of security should reduce 
risks encumbent in sensitive programs. 

5. DD/S$T recommends that recommendation 4c of the IG 
report be revised to read as follows: 


The Office of Security should be given prime 
responsibility to ensure the enforcement of security 
standards prescribed for CIA contractors. As one 
measure toward this end the Office of Security should 
establish. a security audit unit to conduct industrial 
security inspections (announced and unannounced) of 
Program Management and of its contractors. Results of 
such audits should be provided to the Deputy Director 
of the component involved, the IG, the DDCI and the DCI ” 
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D ear : 

The purpose of this letter is to bring to your attention 
a matter of urgent importance to the national security inter- 
ests of this country, and to seek your assistance. 

W i t h i n t h e last few weeks, J h a v e caused sur p r i s e s e c u r i t v 
inspections to be conducted at the facilities of several major 
contractors engaged in the performance of contracts funded q, 
administered by this Agency. The results have been uniformly 
disappointing, and in some aspects appalling. In each 
instance, numerous and serious d e f i c i e n c i e s were found t o e x i s i. 
in the security programs of those contractors whose facilities 
v.eie surveyed. Putting aside the specifics, however, I believe 
the larger point confirmed by these surveys is that security 
has been treated as a distinctly secondary aspect of contract 
pet f o i mu ii i, 6 and that it has received only such attention and 
t esom ces as may have been left over after other tasks, evi- 
dently seen by the contractors involved as more pressing, 
were fulfilled. In most instances, it is an attitude of casual •• 
ness t ha l leaves us vulnerable lo os pi a nape or inadvertent It'-. ■ 

‘ 1 ' : ; • i '- 1 - r -u- <. u : tin \ t o i .. t moms e i v e s . 

I want to make it c ) e a r that I regard security as being 
o ' central importance in the performance of contracts funded or 
a d m i n is to red by t h i s A g e :: c y . h • a r 1 y all of t h o v;>! r v r . a e r 
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contr .ct would be of lessor value, and much of it would be of 
little value, if it could not be performed in a secure manner 
and protected against unauthorized disclosure, whether deliber- 
ate or inadvertent, which I have the statutory obligation to 
prevent. 

I am sure you will agree with me that there is no room for 
relaxed or casual approaches in this field, and that strict 
adherence to proper security procedures deserves a top manage- 
ment priority on a continuing basis to assure that risks of 

compromise are held to an absolute minimum. For my part, I have 

_ ■* 

directed that the Agency add s i g n i f i c~atii 1 1 y to its industrial 
security staffing so as to support a new program of unannounced 

security audits. When and if siren aard.it s reveal serious dis- 

/ 

v : ■ 

crepancies, 1 will have to reviev; a-dl recourses available to me 
to ensure security, irrcluding the withdrawal of security clear- 

4k 

ances from plants and/or individuals. I have directed other 
initiatives as well, including the requirement that a contractor 

f, - 

security record and posture be taken into account when it comes 
to the award of new contracts and more effective provisions 
within our contracts with aspect to security. ? 

I hope that you will join w i t ii me in my resolve to bring 

about and maintain higher 1 ev :• 1 s of consc i oneness and higher 
standards of performance with regal'd to security aspects of Age :ic 
contracts. I am counting on your cooperation 1 . 

Yours, ■ ' 

« 

- ; 

STANS FI ELD TURNER . J : 

< 
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